CVE-2011-4024: XSS
Published Oct 21, 2011
·Updated
Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
13 affected components
Ocsinventory-ng Ocs Inventory Ng=1.0
Ocsinventory-ng Ocs Inventory Ng=1.02
Ocsinventory-ng Ocs Inventory Ng=1.0-beta
Ocsinventory-ng Ocs Inventory Ng=1.01
Ocsinventory-ng Ocs Inventory Ng<=2.0.1
Ocsinventory-ng Ocs Inventory Ng=1.0-rc3-1
Ocsinventory-ng Ocs Inventory Ng=1.02-rc2
Ocsinventory-ng Ocs Inventory Ng=1.02-rc1
Ocsinventory-ng Ocs Inventory Ng=1.02.1
Ocsinventory-ng Ocs Inventory Ng=1.0-rc1
Ocsinventory-ng Ocs Inventory Ng=1.02-rc3
Ocsinventory-ng Ocs Inventory Ng=1.0-rc3
Ocsinventory-ng Ocs Inventory Ng=1.0-rc2
Remediation
Event History
Oct 21, 2011
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4024?
CVE-2011-4024 is categorized as a high-severity vulnerability due to its potential for remote exploitation through cross-site scripting.
2
How do I fix CVE-2011-4024?
To mitigate CVE-2011-4024, upgrade OCS Inventory NG to version 2.0.2 or later, which addresses the vulnerability.
3
What software versions are affected by CVE-2011-4024?
CVE-2011-4024 affects OCS Inventory NG versions up to and including 2.0.1.
4
Can CVE-2011-4024 lead to data theft?
Yes, exploitations of CVE-2011-4024 can allow attackers to inject malicious scripts, potentially leading to data theft.
5
Who can be targeted by CVE-2011-4024?
CVE-2011-4024 can target users of the affected versions of OCS Inventory NG who access compromised web pages.